Person using a laptop fingerprint sensor for secure passwordless authentication.

Passwords remain one of the weakest points in business security.

People reuse them across accounts, forget them, write them down, and — perhaps most dangerously — enter them into convincing fake login pages without realising they’ve been tricked.

Passkeys are designed to remove many of those problems entirely.

A passkey lets you sign in using the same fingerprint, face scan, or PIN you already use to unlock your phone or laptop. There’s no password to type, remember, reuse, or hand over to a phishing site.

Behind the scenes, passkeys use the FIDO security standard, which is supported by major technology companies including Apple, Google, and Microsoft. Because the passkey is tied to the legitimate website or service where it was created, a fake login page cannot simply trick you into handing it over.

For businesses, that makes passkeys one of the most promising ways to strengthen authentication without making signing in more complicated for your staff.

Here’s how they work, why they’re harder to attack than passwords, and where your business can start using them.


What is a passkey?

A passkey replaces a traditional password with the security built into your device.

Instead of typing a password, you prove that you’re the person who owns the device using the same method you already use to unlock it — such as a fingerprint, face scan, or PIN.

When you create a passkey for a website or application, your device generates two linked cryptographic keys.

The private key stays securely on your device and isn’t shared with the website.

The public key is stored by the service you’re signing into.

When you log in, the website sends your device a challenge. Your device uses the private key to respond, but only after you’ve unlocked it with your fingerprint, face, or PIN.

The website can verify the response using the public key and let you in.

There is no password being transmitted because there isn’t a password involved.

Passkeys are based on the FIDO standard, which is supported by Apple, Google, Microsoft and many other technology providers.

Why passkeys are harder to attack than passwords

The biggest problem with passwords is that they are shared secrets.

You know the password, but the service you’re logging into also needs to be able to verify it. Attackers therefore have something valuable to steal, guess, reuse or trick you into entering.

Passkeys work differently.

They are resistant to phishing

A passkey is tied to the website or service where it was created.

If you click a phishing link and land on a convincing fake Microsoft 365 login page, your passkey won’t simply be handed over to the attacker. It is associated with the legitimate site, so the fake site can’t use it as though it were the real thing.

That’s particularly important because phishing remains one of the most common ways attackers get into business accounts.

There’s no password waiting to be stolen

A website stores your public key rather than a password.

Even if that service is breached, attackers don’t get a password they can try against your other accounts.

That removes one of the biggest problems with traditional authentication: stolen passwords being reused elsewhere.

There’s nothing to reuse or remember

Every passkey is unique to the service where it was created.

You don’t need to come up with another complicated password, remember it, store it in a spreadsheet, or reuse an existing one because you can’t think of anything else.

That makes passkeys particularly useful for reducing the risks created by password reuse.

Older authentication methods, including text-message codes and some app approval prompts, can still be manipulated or tricked out of users. Passkeys remove much of that opportunity because there is no secret for the user to disclose.


Where can you use passkeys already?

Passkey support has expanded quickly.

You can already use passkeys with services from Microsoft, Google and Apple, alongside a growing number of banks, password managers and business applications.

Apple, Google and Microsoft have also built passkey support into their devices, operating systems and browsers. In many cases, the phone or laptop your staff already use can store and use passkeys without requiring additional hardware.

There are two types worth knowing about.

Synced passkeys are backed up through an account such as Apple, Google or Microsoft. This means they can be available across multiple devices and can be recovered if one device is lost.

Device-bound passkeys stay on a particular device. A physical security key is one example. These provide a more tightly controlled option and can be particularly appropriate for highly sensitive accounts.

Should your business start using passkeys?

For most businesses, yes.

That doesn’t mean you need to replace every password overnight. A gradual rollout is a much more practical approach.

If your business uses Microsoft 365, passkeys are already available through Microsoft Entra. Users can authenticate using a passkey stored through Microsoft Authenticator, a security key or a supported device.

Google Workspace supports passkeys too, and support across other business applications continues to grow.

There is also a usability benefit.

Microsoft reports that signing in with a synced passkey can take around three seconds, compared with roughly 69 seconds for a password followed by traditional multi-factor authentication. For an individual, that’s a small difference. Across an entire workforce signing in repeatedly throughout the day, it can add up.

A sensible way to start

1. Start with your most sensitive accounts: Prioritise administrators, finance users and anyone who can move money, access highly confidential information or make significant changes to your systems.

2. Give other staff the option to add passkeys: You don’t have to remove passwords immediately. Allowing users to add a passkey alongside their existing authentication gives everyone time to become familiar with the new process.

3. Plan for recovery: Make sure each user has an appropriate backup, such as a second registered device or security key. Losing a phone shouldn’t mean losing access to a business account.

Your IT provider can help configure the necessary Microsoft Entra policies and manage the rollout so authentication changes don’t accidentally lock people out.

What should you watch out for?

Passkeys remove many password-related risks, but they’re not something you can simply switch on and forget about.

  • Account recovery: If someone loses the only device containing their passkey and has no backup, they could be locked out. Synced passkeys can help here, as can registering a second device or security key. The important part is arranging that recovery option before something goes wrong.
  • Not every application supports them yet: Passkey adoption is growing rapidly, but some older systems and smaller software providers still rely on passwords.For most businesses, that means running passwords and passkeys alongside one another for a while rather than attempting an overnight switch.
  • Shared devices and accounts need extra thought: Passkeys are designed around individual users and their devices. If your business still has shared computers or shared accounts, you’ll need to decide how authentication should work in those situations rather than simply assuming a passkey will fit the existing setup.

Where to start

You don’t need to wait for passwords to become a problem before doing something about them.

We can help you start by identifying the accounts where a compromised password would cause the most damage. Administrator accounts, finance systems and accounts with access to sensitive business information are good candidates.

The biggest advantage of passkeys is that they improve security and make authentication easier for users.

Instead of asking staff to create stronger passwords, remember more passwords and become better at spotting increasingly convincing phishing pages, you’re removing the password from the equation altogether. For businesses already paying for Microsoft 365, passkeys are worth exploring now — particularly for the accounts where a stolen password could do the most damage.

Article used with permission from The Technology Press.


Tags

Comments are closed